Description
In Bootstrap before 4.1.2, XSS is possible in the data-target property of scrollspy.
Remediation
References
Related Vulnerabilities
WordPress Plugin Yoast SEO Cross-Site Scripting (11.5)
WordPress Plugin FL3R FeelBox Multiple Vulnerabilities (8.1)
Sqlite NULL Pointer Dereference Vulnerability (CVE-2020-35525)
Jboss EAP Loop with Unreachable Exit Condition ('Infinite Loop') Vulnerability (CVE-2018-1336)
Liferay Portal Incorrect Default Permissions Vulnerability (CVE-2022-42128)